Microsoft Introduces Exchange V2 Update Following Identification of New Security Vulnerability

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Microsoft Releases September 2026 V2 Security Updates

Microsoft has unveiled its September 2026 V2 security updates aimed at rectifying a significant vulnerability within Exchange Server.

This flaw permits authenticated attackers to access other users’ mailboxes within the same organizational structure.

Designated as CVE-2026-96940, this weakness presents a serious threat, potentially exposing sensitive email messages and attachments, thereby raising alarm for entities utilizing on-premises Exchange systems.

This vulnerability stems from inadequate authorization protocols, enabling an assailant with authenticated access to elevate their privileges across the network.

Public vulnerability databases have assigned a CVSS score of 8.8, indicating a considerable level of risk.

Notably, while some exploitations necessitate user interaction via malicious files, this particular vulnerability allows access without any user engagement. Furthermore, affected mailbox access does not traverse tenant boundaries.

Microsoft reports that its internal teams identified the vulnerability and noted no evidence of active exploitation.

Remarkably, the company confirmed that this update was released ahead of its scheduled timeline; therefore, accompanying documentation may not have been fully available at the time of the announcement.

Microsoft Reissues Exchange Server Update

The September 2026 V2 update enhances the previous September security releases by incorporating protections against CVE-2026-96940.

Organizations that implemented the earlier updates are encouraged to conduct a review of the new packages instead of assuming their servers contain this critical patch.

Updates are available for Exchange Server Subscription Edition RTM, along with Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23.

Administrators are required to select the appropriate package corresponding to their installed version and cumulative update.

This issue is distinct from CVE-2026-62911, an earlier Exchange vulnerability highlighted by Cybersecurity News, following the demonstration of an authentication relay attack.

It is crucial to note that previous research should not be misconstrued as implying the existence of an exploit for CVE-2026-96940.

Exchange Server versions 2016 and 2019 have reached their end of support. Consequently, the latest patches are exclusively accessible to organizations enrolled in Microsoft’s Period 2 Extended Security Update program, which encompasses coverage from May to October 2026.

This Period 2 program necessitates a separate purchase, applicable even for clients who previously joined the initial ESU program.

Microsoft has affirmed that no extensions will be granted post-October. Organizations lacking this coverage are advised to migrate to Exchange Server Subscription Edition to continue receiving essential security updates.

Users of Exchange Online are already safeguarded against the vulnerabilities addressed in this release.

However, businesses employing hybrid configurations must ensure their local Exchange servers are updated, including those designated solely for management purposes. Additionally, systems running Exchange Management Tools require the relevant updates.

To assist administrators, Microsoft recommends executing the Exchange Server Health Checker script to identify any missing cumulative updates, security updates, and required manual interventions.

The Exchange Update Wizard can facilitate planning the appropriate upgrade path before implementing the latest security package.

The security updates are cumulative, meaning that a server operating on a supported cumulative update does not require installation of every preceding security update in order.

After application, administrators should restart the server and verify that Exchange services are functioning correctly, followed by running the Health Checker again to determine any remaining steps.

It is worth noting that the release contains known issues, such as published calendar files returning HTTP 500 errors and ContentEngine deadlocks for emails in the Korean language.

Microsoft has indicated plans to address these issues in forthcoming updates while also rectifying problems related to shared mailbox wrapper messages and delegated mailbox availability in particular hybrid environments.

Modern Microsoft office building with large logo, glass facade, and people walking outside in an urban business setting.

Microsoft urges its customers to assess the deployment guidance and apply the update promptly. For organizations affected, the immediate focus must be on closing the mailbox access vulnerability while ensuring that mail services remain operational and healthy following patch implementation throughout their Exchange infrastructure.

Source link: Cybersecuritynews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Neil Hemmings

I'm Neil Hemmings from Anaheim, CA, with an Associate of Science in Computer Science from Diablo Valley College. As Senior Tech Associate and Content Manager at RS Web Solutions, I write about AI, gadgets, cybersecurity, and apps – sharing hands-on reviews, tutorials, and practical tech insights.
Share the Love
Related News Worth Reading